← Back to overview

A critical command injection vulnerability has been discovered in D-Link DIR-895L firmware version A1_102b07. The flaw exists in the sendACK function within the udhcpcd/serverpacket.c file of the udhcpcd component. An attacker can manipulate the Hostname argument to inject arbitrary commands. The vulnerability is remotely exploitable without physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. The affected component is the DHCP client daemon (udhcpcd), which handles network configuration. This type of vulnerability in home/small business routers poses significant risks to network security. D-Link has been referenced in the advisory, suggesting a vendor patch or advisory may be forthcoming. The issue is tracked under CVE-2026-86295 and has been documented across multiple vulnerability databases including VulDB and NVD.

Affected products

  • D-Link DIR-895L A1_102b07

Related CVE's

  • CVE-2026-86295

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities